Bv9ARM.ch07.html revision ec02e04ead266ebd7796d045b41813aac5499a2b
55cf6e01272ec475edea32aa9b7923de2d36cb42Christian Maeder<HTML
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja Gröning><HEAD
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja Gröning><TITLE
256c49ddf8face2be2205c79158ee76db4e1b4a4Christian Maeder>BIND 9 Security Considerations</TITLE
dfa71f78fc82bc3e69691c77b960d342b1b56257Christian Maeder><META
98890889ffb2e8f6f722b00e265a211f13b5a861Corneliu-Claudiu ProdescuNAME="GENERATOR"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningCONTENT="Modular DocBook HTML Stylesheet Version 1.61
3f69b6948966979163bdfe8331c38833d5d90ecdChristian Maeder"><LINK
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningREL="HOME"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningTITLE="BIND 9 Administrator Reference Manual"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningHREF="Bv9ARM.html"><LINK
0280e3d39b760dfda9af58cf60b397cd64638f29Christian MaederREL="PREVIOUS"
256c49ddf8face2be2205c79158ee76db4e1b4a4Christian MaederTITLE="BIND 9 Configuration Reference"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningHREF="Bv9ARM.ch06.html"><LINK
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningREL="NEXT"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningTITLE="Troubleshooting"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningHREF="Bv9ARM.ch08.html"></HEAD
729aff22a7983f5bb113dcc604157edd728c1484Christian Maeder><BODY
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningCLASS="chapter"
bc09240e7ef99954c3ef3919ccd348cccbdde7d7Sonja GröningBGCOLOR="#FFFFFF"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningTEXT="#000000"
b9445c244f52509c5fe6ed65459e98289638f4c1Sonja GröningLINK="#0000FF"
e7ce154edb906685b3fa7f6c0a764e18a4658068Christian MaederVLINK="#840084"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningALINK="#0000FF"
62ecb1e7f8fd9573eea8369657de12c7bf9f4f25Christian Maeder><DIV
f553bbeec7270566223902c808cbac9b5ae45c84Sonja GröningCLASS="NAVHEADER"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja Gröning><TABLE
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningWIDTH="100%"
d5ef5a29a89fa5548f81fcd49fcf0ffda69d45b0Christian MaederBORDER="0"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningCELLPADDING="0"
e79472ac9f45b44b205357ff33965c36bfe6f765Christian MaederCELLSPACING="0"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja Gröning><TR
4ef2a978e66e2246ff0b7f00c77deb7aabb28b8eChristian Maeder><TH
4ef2a978e66e2246ff0b7f00c77deb7aabb28b8eChristian MaederCOLSPAN="3"
4ef2a978e66e2246ff0b7f00c77deb7aabb28b8eChristian MaederALIGN="center"
c200224a127278d54634ca4a5079591cb989aaf3Christian Maeder>BIND 9 Administrator Reference Manual</TH
ad270004874ce1d0697fb30d7309f180553bb315Christian Maeder></TR
ad187062b0009820118c1b773a232e29b879a2faChristian Maeder><TR
0280e3d39b760dfda9af58cf60b397cd64638f29Christian Maeder><TD
4ef2a978e66e2246ff0b7f00c77deb7aabb28b8eChristian MaederWIDTH="10%"
c200224a127278d54634ca4a5079591cb989aaf3Christian MaederALIGN="left"
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederVALIGN="bottom"
4ef2a978e66e2246ff0b7f00c77deb7aabb28b8eChristian Maeder><A
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningHREF="Bv9ARM.ch06.html"
120c9bff9059626735fc12b0399dcc9e5a62c345Christian Maeder>Prev</A
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja Gröning></TD
616b72452ce5a75ade1a11ccc2c9671b3444558eChristian Maeder><TD
b0e1fc32ecf1a0ad4c91dedbd6aef5c7ed215a82Christian MaederWIDTH="80%"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningALIGN="center"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningVALIGN="bottom"
7c2d602a73afe304ac0ca225ecff42b2ae8bdab3Christian Maeder></TD
e7ce154edb906685b3fa7f6c0a764e18a4658068Christian Maeder><TD
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningWIDTH="10%"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningALIGN="right"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningVALIGN="bottom"
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder><A
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederHREF="Bv9ARM.ch08.html"
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder>Next</A
7c2d602a73afe304ac0ca225ecff42b2ae8bdab3Christian Maeder></TD
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder></TR
bba825b39570777866d560bfde3807731131097eKlaus Luettich></TABLE
bba825b39570777866d560bfde3807731131097eKlaus Luettich><HR
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian MaederALIGN="LEFT"
7592d4dc0461feff73113f4679e0b1823fd117faChristian MaederWIDTH="100%"></DIV
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder><DIV
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja GröningCLASS="chapter"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder><H1
42c01284bba8d7c8d995c8dfb96ace57d28ed1bcTill Mossakowski><A
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederNAME="ch07"
2018084d6189a68640c516ca3e340d879f40f0acChristian Maeder>Chapter 7. <SPAN
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningCLASS="acronym"
dfa71f78fc82bc3e69691c77b960d342b1b56257Christian Maeder>BIND</SPAN
7f6b97541fdee30d62a0a3cfa58173212a6cd002Christian Maeder> 9 Security Considerations</A
7f6b97541fdee30d62a0a3cfa58173212a6cd002Christian Maeder></H1
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja Gröning><DIV
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederCLASS="TOC"
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder><DL
578b677874296e4ba48e57b5e4b4b0270d995603Christian Maeder><DT
7bd5754e08c0e163f96fff840189a38394f96af0Tina Kraußer><B
308e5e525d705de2c8a90ff512da31c323869f56Sonja Gröning>Table of Contents</B
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder></DT
a74f814d3b445eadad6f68737a98a7a303698affChristian Maeder><DT
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>7.1. <A
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja GröningHREF="Bv9ARM.ch07.html#Access_Control_Lists"
308e5e525d705de2c8a90ff512da31c323869f56Sonja Gröning>Access Control Lists</A
a74f814d3b445eadad6f68737a98a7a303698affChristian Maeder></DT
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder><DT
415c4845009d24c52c402431263b50f3cc1c3aa1Sonja Gröning>7.2. <A
308e5e525d705de2c8a90ff512da31c323869f56Sonja GröningHREF="Bv9ARM.ch07.html#AEN4316"
bb027d3cacbd83dfec98beb38001f105e4918557Christian Maeder><B
b172714c339053a40393dc0cf4f9151c97695e01Till MossakowskiCLASS="command"
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>chroot</B
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder> and <B
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian MaederCLASS="command"
a3acfcfbd58cc5529becffcda29f7de49f9500a7Christian Maeder>setuid</B
13ed13e06a5dd4aad12044ed7e7503cbe7f62990Christian Maeder> (for
a3acfcfbd58cc5529becffcda29f7de49f9500a7Christian MaederUNIX servers)</A
3cc55a325643548e442f1b673f694a2bf621f519Sonja Gröning></DT
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja Gröning><DT
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>7.3. <A
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian MaederHREF="Bv9ARM.ch07.html#dynamic_update_security"
ad187062b0009820118c1b773a232e29b879a2faChristian Maeder>Dynamic Update Security</A
ad187062b0009820118c1b773a232e29b879a2faChristian Maeder></DT
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder></DL
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder></DIV
dfa71f78fc82bc3e69691c77b960d342b1b56257Christian Maeder><DIV
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja GröningCLASS="sect1"
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder><H1
ad187062b0009820118c1b773a232e29b879a2faChristian MaederCLASS="sect1"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder><A
3cc55a325643548e442f1b673f694a2bf621f519Sonja GröningNAME="Access_Control_Lists"
f7e2a8c0a9894541a32d40e93b56245886166eb9Christian Maeder>7.1. Access Control Lists</A
acc0b88aa24f7228afad60770118be9950ba5a8eChristian Maeder></H1
f7e2a8c0a9894541a32d40e93b56245886166eb9Christian Maeder><P
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>Access Control Lists (ACLs), are address match lists that
8b66de47c89e252c907c8ed3a5ccd16dbccbfb3eChristian Maederyou can set up and nickname for future use in <B
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja GröningCLASS="command"
dfa71f78fc82bc3e69691c77b960d342b1b56257Christian Maeder>allow-notify</B
308e5e525d705de2c8a90ff512da31c323869f56Sonja Gröning>,
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder<B
3cc55a325643548e442f1b673f694a2bf621f519Sonja GröningCLASS="command"
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>allow-query</B
3cc55a325643548e442f1b673f694a2bf621f519Sonja Gröning>, <B
3cc55a325643548e442f1b673f694a2bf621f519Sonja GröningCLASS="command"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>allow-recursion</B
415c4845009d24c52c402431263b50f3cc1c3aa1Sonja Gröning>,
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja Gröning<B
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningCLASS="command"
d17834302eaa101395b4b806cd73670fd864445fChristian Maeder>blackhole</B
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja Gröning>, <B
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja GröningCLASS="command"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja Gröning>allow-transfer</B
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>,
d48085f765fca838c1d972d2123601997174583dChristian Maederetc.</P
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder><P
d48085f765fca838c1d972d2123601997174583dChristian Maeder>Using ACLs allows you to have finer control over who can access
d48085f765fca838c1d972d2123601997174583dChristian Maederyour name server, without cluttering up your config files with huge
d48085f765fca838c1d972d2123601997174583dChristian Maederlists of IP addresses.</P
d48085f765fca838c1d972d2123601997174583dChristian Maeder><P
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>It is a <I
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian MaederCLASS="emphasis"
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>good idea</I
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder> to use ACLs, and to
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maedercontrol access to your server. Limiting access to your server by
d48085f765fca838c1d972d2123601997174583dChristian Maederoutside parties can help prevent spoofing and DoS attacks against
120c9bff9059626735fc12b0399dcc9e5a62c345Christian Maederyour server.</P
62dd3cd58cda003c32ac69ff12dc82b0a6f5d9d3Christian Maeder><P
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>Here is an example of how to properly apply ACLs:</P
62dd3cd58cda003c32ac69ff12dc82b0a6f5d9d3Christian Maeder><PRE
4ef2a978e66e2246ff0b7f00c77deb7aabb28b8eChristian MaederCLASS="programlisting"
3cc55a325643548e442f1b673f694a2bf621f519Sonja Gröning>&#13;// Set up an ACL named "bogusnets" that will block RFC1918 space,
dfa71f78fc82bc3e69691c77b960d342b1b56257Christian Maeder// which is commonly used in spoofing attacks.
308e5e525d705de2c8a90ff512da31c323869f56Sonja Gröningacl bogusnets { 0.0.0.0/8; 1.0.0.0/8; 2.0.0.0/8; 192.0.2.0/24; 224.0.0.0/3; 10.0.0.0/8; 172.16.0.0/12; 192.168.0.0/16; };
bb027d3cacbd83dfec98beb38001f105e4918557Christian Maeder// Set up an ACL called our-nets. Replace this with the real IP numbers.
3cc55a325643548e442f1b673f694a2bf621f519Sonja Gröningacl our-nets { x.x.x.x/24; x.x.x.x/21; };
308e5e525d705de2c8a90ff512da31c323869f56Sonja Gröningoptions {
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder ...
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder ...
3cc55a325643548e442f1b673f694a2bf621f519Sonja Gröning allow-query { our-nets; };
308e5e525d705de2c8a90ff512da31c323869f56Sonja Gröning allow-recursion { our-nets; };
bb027d3cacbd83dfec98beb38001f105e4918557Christian Maeder ...
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder blackhole { bogusnets; };
90d97972167d142dde6ee8b18d9625332040261fJonathan von Schroeder ...
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder};
acc0b88aa24f7228afad60770118be9950ba5a8eChristian Maederzone "example.com" {
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder type master;
3cc55a325643548e442f1b673f694a2bf621f519Sonja Gröning file "m/example.com";
308e5e525d705de2c8a90ff512da31c323869f56Sonja Gröning allow-query { any; };
3cc55a325643548e442f1b673f694a2bf621f519Sonja Gröning};
13ed13e06a5dd4aad12044ed7e7503cbe7f62990Christian Maeder</PRE
3cc55a325643548e442f1b673f694a2bf621f519Sonja Gröning><P
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja Gröning>This allows recursive queries of the server from the outside
bb027d3cacbd83dfec98beb38001f105e4918557Christian Maederunless recursion has been previously disabled.</P
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder><P
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja Gröning>For more information on how to use ACLs to protect your server,
3cc55a325643548e442f1b673f694a2bf621f519Sonja Gröningsee the <I
acc0b88aa24f7228afad60770118be9950ba5a8eChristian MaederCLASS="emphasis"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>AUSCERT</I
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder> advisory at
415c4845009d24c52c402431263b50f3cc1c3aa1Sonja Gröning<A
dfa71f78fc82bc3e69691c77b960d342b1b56257Christian MaederHREF="ftp://ftp.auscert.org.au/pub/auscert/advisory/AL-1999.004.dns_dos"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningTARGET="_top"
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>ftp://ftp.auscert.org.au/pub/auscert/advisory/AL-1999.004.dns_dos</A
7de39d39bc1700cc8a9bb9df90b920aad9e18d4aChristian Maeder></P
13ed13e06a5dd4aad12044ed7e7503cbe7f62990Christian Maeder></DIV
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja Gröning><DIV
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja GröningCLASS="sect1"
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja Gröning><H1
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederCLASS="sect1"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder><A
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja GröningNAME="AEN4316"
e7ce154edb906685b3fa7f6c0a764e18a4658068Christian Maeder>7.2. <B
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja GröningCLASS="command"
7de39d39bc1700cc8a9bb9df90b920aad9e18d4aChristian Maeder>chroot</B
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder> and <B
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederCLASS="command"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>setuid</B
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder> (for
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederUNIX servers)</A
d5ef5a29a89fa5548f81fcd49fcf0ffda69d45b0Christian Maeder></H1
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder><P
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>On UNIX servers, it is possible to run <SPAN
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian MaederCLASS="acronym"
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder>BIND</SPAN
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja Gröning> in a <I
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja GröningCLASS="emphasis"
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder>chrooted</I
29379037d0a2fc17c96c49bd343a3f276a5b34a6Christian Maeder> environment
29379037d0a2fc17c96c49bd343a3f276a5b34a6Christian Maeder(<B
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederCLASS="command"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>chroot()</B
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>) by specifying the "<TT
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederCLASS="option"
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>-t</TT
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder>"
29379037d0a2fc17c96c49bd343a3f276a5b34a6Christian Maederoption. This can help improve system security by placing <SPAN
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian MaederCLASS="acronym"
29379037d0a2fc17c96c49bd343a3f276a5b34a6Christian Maeder>BIND</SPAN
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder> in
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maedera "sandbox", which will limit the damage done if a server is compromised.</P
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder><P
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>Another useful feature in the UNIX version of <SPAN
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian MaederCLASS="acronym"
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder>BIND</SPAN
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder> is the
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maederability to run the daemon as an unprivileged user ( <TT
29379037d0a2fc17c96c49bd343a3f276a5b34a6Christian MaederCLASS="option"
29379037d0a2fc17c96c49bd343a3f276a5b34a6Christian Maeder>-u</TT
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder> <TT
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian MaederCLASS="replaceable"
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder><I
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder>user</I
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder></TT
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder> ).
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian MaederWe suggest running as an unprivileged user when using the <B
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederCLASS="command"
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>chroot</B
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder> feature.</P
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder><P
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder>Here is an example command line to load <SPAN
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian MaederCLASS="acronym"
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>BIND</SPAN
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder> in a <B
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian MaederCLASS="command"
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder>chroot()</B
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder> sandbox,
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder<B
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian MaederCLASS="command"
29379037d0a2fc17c96c49bd343a3f276a5b34a6Christian Maeder>/var/named</B
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder>, and to run <B
13ed13e06a5dd4aad12044ed7e7503cbe7f62990Christian MaederCLASS="command"
29379037d0a2fc17c96c49bd343a3f276a5b34a6Christian Maeder>named</B
29379037d0a2fc17c96c49bd343a3f276a5b34a6Christian Maeder> <B
4ef2a978e66e2246ff0b7f00c77deb7aabb28b8eChristian MaederCLASS="command"
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder>setuid</B
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder> to
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maederuser 202:</P
f7e2a8c0a9894541a32d40e93b56245886166eb9Christian Maeder><P
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder><TT
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian MaederCLASS="userinput"
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder><B
adfdcfa67b7f12df6df7292e238c3f9a4b637980Christian Maeder>/usr/local/bin/named -u 202 -t /var/named</B
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder></TT
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder></P
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder><DIV
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian MaederCLASS="sect2"
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder><H2
1b0c23bf2a0099c05afaf82b81e96706becaf2abSonja GröningCLASS="sect2"
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder><A
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederNAME="AEN4339"
f7e2a8c0a9894541a32d40e93b56245886166eb9Christian Maeder>7.2.1. The <B
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian MaederCLASS="command"
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder>chroot</B
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder> Environment</A
1b0c23bf2a0099c05afaf82b81e96706becaf2abSonja Gröning></H2
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder><P
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder>In order for a <B
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederCLASS="command"
f7e2a8c0a9894541a32d40e93b56245886166eb9Christian Maeder>chroot()</B
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder> environment to
d48085f765fca838c1d972d2123601997174583dChristian Maederwork properly in a particular directory
d48085f765fca838c1d972d2123601997174583dChristian Maeder(for example, <TT
d48085f765fca838c1d972d2123601997174583dChristian MaederCLASS="filename"
d2c0d3f631dda5a820e7026e22020e67e81a6137Sonja Gröning>/var/named</TT
308e5e525d705de2c8a90ff512da31c323869f56Sonja Gröning>),
f553bbeec7270566223902c808cbac9b5ae45c84Sonja Gröningyou will need to set up an environment that includes everything
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder<SPAN
0a949218a70362623507292d2f47252e900a7c1cChristian MaederCLASS="acronym"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>BIND</SPAN
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder> needs to run.
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian MaederFrom <SPAN
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian MaederCLASS="acronym"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>BIND</SPAN
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>'s point of view, <TT
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian MaederCLASS="filename"
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder>/var/named</TT
7798d5bdd93a57b23e514271944b2191e0c4cbb2Christian Maeder> is
0a949218a70362623507292d2f47252e900a7c1cChristian Maederthe root of the filesystem. You will need to adjust the values of options like
0a949218a70362623507292d2f47252e900a7c1cChristian Maederlike <B
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederCLASS="command"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>directory</B
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder> and <B
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja GröningCLASS="command"
dfa71f78fc82bc3e69691c77b960d342b1b56257Christian Maeder>pid-file</B
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja Gröning> to account
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja Gröningfor this.
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja Gröning</P
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder><P
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja Gröning>&#13;Unlike with earlier versions of BIND, you will typically
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder<I
3015a81bddf37523e8a2e9c4e29218d8d57b3c9bPaolo TorriniCLASS="emphasis"
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder>not</I
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder> need to compile <B
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja GröningCLASS="command"
dfa71f78fc82bc3e69691c77b960d342b1b56257Christian Maeder>named</B
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja Gröning>
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja Gröningstatically nor install shared libraries under the new root.
4a1eac1b489ea6212d1d66ae9d9dd8802924885cSonja GröningHowever, depending on your operating system, you may need
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maederto set up things like
e7100d3d181d62ba331b9513529dc304915d4751Christian Maeder<TT
308e5e525d705de2c8a90ff512da31c323869f56Sonja GröningCLASS="filename"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>/dev/zero</TT
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>,
308e5e525d705de2c8a90ff512da31c323869f56Sonja Gröning<TT
29379037d0a2fc17c96c49bd343a3f276a5b34a6Christian MaederCLASS="filename"
29379037d0a2fc17c96c49bd343a3f276a5b34a6Christian Maeder>/dev/random</TT
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>,
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder<TT
adfdcfa67b7f12df6df7292e238c3f9a4b637980Christian MaederCLASS="filename"
13ed13e06a5dd4aad12044ed7e7503cbe7f62990Christian Maeder>/dev/log</TT
c8af0e935919ab2d579a649f57cafb333ee971dfSonja Gröning>, and/or
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder<TT
0a949218a70362623507292d2f47252e900a7c1cChristian MaederCLASS="filename"
308e5e525d705de2c8a90ff512da31c323869f56Sonja Gröning>/etc/localtime</TT
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja Gröning>.
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja Gröning</P
308e5e525d705de2c8a90ff512da31c323869f56Sonja Gröning></DIV
29379037d0a2fc17c96c49bd343a3f276a5b34a6Christian Maeder><DIV
29379037d0a2fc17c96c49bd343a3f276a5b34a6Christian MaederCLASS="sect2"
adfdcfa67b7f12df6df7292e238c3f9a4b637980Christian Maeder><H2
0a949218a70362623507292d2f47252e900a7c1cChristian MaederCLASS="sect2"
13ed13e06a5dd4aad12044ed7e7503cbe7f62990Christian Maeder><A
308e5e525d705de2c8a90ff512da31c323869f56Sonja GröningNAME="AEN4357"
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder>7.2.2. Using the <B
308e5e525d705de2c8a90ff512da31c323869f56Sonja GröningCLASS="command"
308e5e525d705de2c8a90ff512da31c323869f56Sonja Gröning>setuid</B
308e5e525d705de2c8a90ff512da31c323869f56Sonja Gröning> Function</A
308e5e525d705de2c8a90ff512da31c323869f56Sonja Gröning></H2
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder><P
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>Prior to running the <B
308e5e525d705de2c8a90ff512da31c323869f56Sonja GröningCLASS="command"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>named</B
29379037d0a2fc17c96c49bd343a3f276a5b34a6Christian Maeder> daemon, use
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maederthe <B
0a949218a70362623507292d2f47252e900a7c1cChristian MaederCLASS="command"
bc1d1f0cdb992f8a2ae4129d8f46ea5087de6b71Christian Maeder>touch</B
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder> utility (to change file access and
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maedermodification times) or the <B
0a949218a70362623507292d2f47252e900a7c1cChristian MaederCLASS="command"
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>chown</B
d5ef5a29a89fa5548f81fcd49fcf0ffda69d45b0Christian Maeder> utility (to
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maederset the user id and/or group id) on files
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja Gröningto which you want <SPAN
dfa71f78fc82bc3e69691c77b960d342b1b56257Christian MaederCLASS="acronym"
0bbf8016424222f40f8cf8dc912632cd93bd5429Sonja Gröning>BIND</SPAN
c8af0e935919ab2d579a649f57cafb333ee971dfSonja Gröning>
0747dcf8f71ed2be4410d811364fcd8d13e6a0f9Sonja Gröningto write. Note that if the <B
0747dcf8f71ed2be4410d811364fcd8d13e6a0f9Sonja GröningCLASS="command"
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>named</B
c8af0e935919ab2d579a649f57cafb333ee971dfSonja Gröning> daemon is running as an
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja Gröningunprivileged user, it will not be able to bind to new restricted ports if the
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maederserver is reloaded.</P
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder></DIV
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder></DIV
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder><DIV
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian MaederCLASS="sect1"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder><H1
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederCLASS="sect1"
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder><A
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja GröningNAME="dynamic_update_security"
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder>7.3. Dynamic Update Security</A
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder></H1
0a949218a70362623507292d2f47252e900a7c1cChristian Maeder><P
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>Access to the dynamic
0a949218a70362623507292d2f47252e900a7c1cChristian Maederupdate facility should be strictly limited. In earlier versions of
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder<SPAN
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian MaederCLASS="acronym"
c8af0e935919ab2d579a649f57cafb333ee971dfSonja Gröning>BIND</SPAN
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja Gröning> the only way to do this was based on the IP
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja Gröningaddress of the host requesting the update, by listing an IP address or
c200224a127278d54634ca4a5079591cb989aaf3Christian Maedernetwork prefix in the <B
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederCLASS="command"
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja Gröning>allow-update</B
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja Gröning> zone option.
7de39d39bc1700cc8a9bb9df90b920aad9e18d4aChristian MaederThis method is insecure since the source address of the update UDP packet
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maederis easily forged. Also note that if the IP addresses allowed by the
88ece6e49930670e8fd3ee79c89a2e918d2fbd0cChristian Maeder<B
6e39bfd041946fce4982ac89834be73fd1bfb39aChristian MaederCLASS="command"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>allow-update</B
d5ef5a29a89fa5548f81fcd49fcf0ffda69d45b0Christian Maeder> option include the address of a slave
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja Gröningserver which performs forwarding of dynamic updates, the master can be
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maedertrivially attacked by sending the update to the slave, which will
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maederforward it to the master with its own source IP address causing the
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja Gröningmaster to approve it without question.</P
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja Gröning><P
7de39d39bc1700cc8a9bb9df90b920aad9e18d4aChristian Maeder>For these reasons, we strongly recommend that updates be
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maedercryptographically authenticated by means of transaction signatures
c8af0e935919ab2d579a649f57cafb333ee971dfSonja Gröning(TSIG). That is, the <B
d1012ae182d765c4e6986029d210b9e7b48de205Christian MaederCLASS="command"
c8af0e935919ab2d579a649f57cafb333ee971dfSonja Gröning>allow-update</B
c8af0e935919ab2d579a649f57cafb333ee971dfSonja Gröning> option should
f7e2a8c0a9894541a32d40e93b56245886166eb9Christian Maederlist only TSIG key names, not IP addresses or network
f7e2a8c0a9894541a32d40e93b56245886166eb9Christian Maederprefixes. Alternatively, the new <B
f7e2a8c0a9894541a32d40e93b56245886166eb9Christian MaederCLASS="command"
9d75ab580dbf51b7ca60903fb32e7f38d939d326Christian Maeder>update-policy</B
9d75ab580dbf51b7ca60903fb32e7f38d939d326Christian Maeder>
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maederoption can be used.</P
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder><P
d48085f765fca838c1d972d2123601997174583dChristian Maeder>Some sites choose to keep all dynamically updated DNS data
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maederin a subdomain and delegate that subdomain to a separate zone. This
d48085f765fca838c1d972d2123601997174583dChristian Maederway, the top-level zone containing critical data such as the IP addresses
d48085f765fca838c1d972d2123601997174583dChristian Maederof public web and mail servers need not allow dynamic update at
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maederall.</P
d48085f765fca838c1d972d2123601997174583dChristian Maeder></DIV
d48085f765fca838c1d972d2123601997174583dChristian Maeder></DIV
c8af0e935919ab2d579a649f57cafb333ee971dfSonja Gröning><DIV
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederCLASS="NAVFOOTER"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder><HR
7de39d39bc1700cc8a9bb9df90b920aad9e18d4aChristian MaederALIGN="LEFT"
fbd9485e027b53cca7e090991da2b155d680f2f4Sonja GröningWIDTH="100%"><TABLE
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian MaederWIDTH="100%"
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja GröningBORDER="0"
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja GröningCELLPADDING="0"
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja GröningCELLSPACING="0"
adfdcfa67b7f12df6df7292e238c3f9a4b637980Christian Maeder><TR
9d75ab580dbf51b7ca60903fb32e7f38d939d326Christian Maeder><TD
7de39d39bc1700cc8a9bb9df90b920aad9e18d4aChristian MaederWIDTH="33%"
9d75ab580dbf51b7ca60903fb32e7f38d939d326Christian MaederALIGN="left"
9d75ab580dbf51b7ca60903fb32e7f38d939d326Christian MaederVALIGN="top"
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja Gröning><A
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederHREF="Bv9ARM.ch06.html"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>Prev</A
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder></TD
c8af0e935919ab2d579a649f57cafb333ee971dfSonja Gröning><TD
0a949218a70362623507292d2f47252e900a7c1cChristian MaederWIDTH="34%"
0a949218a70362623507292d2f47252e900a7c1cChristian MaederALIGN="center"
0a949218a70362623507292d2f47252e900a7c1cChristian MaederVALIGN="top"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder><A
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederHREF="Bv9ARM.html"
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder>Home</A
42c01284bba8d7c8d995c8dfb96ace57d28ed1bcTill Mossakowski></TD
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja Gröning><TD
adfdcfa67b7f12df6df7292e238c3f9a4b637980Christian MaederWIDTH="33%"
c200224a127278d54634ca4a5079591cb989aaf3Christian MaederALIGN="right"
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederVALIGN="top"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder><A
cf13127b62c0282202ad00844e742a22c84cfac6Christian MaederHREF="Bv9ARM.ch08.html"
cf13127b62c0282202ad00844e742a22c84cfac6Christian Maeder>Next</A
c200224a127278d54634ca4a5079591cb989aaf3Christian Maeder></TD
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja Gröning></TR
c200224a127278d54634ca4a5079591cb989aaf3Christian Maeder><TR
c8af0e935919ab2d579a649f57cafb333ee971dfSonja Gröning><TD
0747dcf8f71ed2be4410d811364fcd8d13e6a0f9Sonja GröningWIDTH="33%"
0747dcf8f71ed2be4410d811364fcd8d13e6a0f9Sonja GröningALIGN="left"
0747dcf8f71ed2be4410d811364fcd8d13e6a0f9Sonja GröningVALIGN="top"
0747dcf8f71ed2be4410d811364fcd8d13e6a0f9Sonja Gröning><SPAN
0747dcf8f71ed2be4410d811364fcd8d13e6a0f9Sonja GröningCLASS="acronym"
0747dcf8f71ed2be4410d811364fcd8d13e6a0f9Sonja Gröning>BIND</SPAN
0747dcf8f71ed2be4410d811364fcd8d13e6a0f9Sonja Gröning> 9 Configuration Reference</TD
0747dcf8f71ed2be4410d811364fcd8d13e6a0f9Sonja Gröning><TD
0747dcf8f71ed2be4410d811364fcd8d13e6a0f9Sonja GröningWIDTH="34%"
0747dcf8f71ed2be4410d811364fcd8d13e6a0f9Sonja GröningALIGN="center"
c8af0e935919ab2d579a649f57cafb333ee971dfSonja GröningVALIGN="top"
c8af0e935919ab2d579a649f57cafb333ee971dfSonja Gröning>&nbsp;</TD
c8af0e935919ab2d579a649f57cafb333ee971dfSonja Gröning><TD
51c96f356eaa4600d90dbddf7f1750295cc923a9Christian MaederWIDTH="33%"
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja GröningALIGN="right"
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja GröningVALIGN="top"
c8af0e935919ab2d579a649f57cafb333ee971dfSonja Gröning>Troubleshooting</TD
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja Gröning></TR
d1012ae182d765c4e6986029d210b9e7b48de205Christian Maeder></TABLE
0d0c6045732f0dcc9c05c05c3efa0d5c5f8e8cc3Sonja Gröning></DIV
364f0bb3cfc316e11127bf22366c6b4c9c3c61dcChristian Maeder></BODY
adfdcfa67b7f12df6df7292e238c3f9a4b637980Christian Maeder></HTML
adfdcfa67b7f12df6df7292e238c3f9a4b637980Christian Maeder>